Skip to main content

CWE archive

CWE-116 CVEs

Programmatic archive

475 CVEs tagged with CWE-11664 Critical, 155 High, 215 Medium, 41 Low, 0 Unrated.

CVE-2022-0220

Published Feb 1, 2022

The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data wit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22992

Published Jan 28, 2022

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the…

CVSS 7.8 · High

CVE-2021-45226

Published Jan 24, 2022

An issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user-controlled HTTP headers, attackers can cause it to send password-reset e-mails pointi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0210

Published Jan 18, 2022

The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the category parameter found in the ~/include/models/model.php fil…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0124

Published Jan 18, 2022

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29872

Published Jan 18, 2022

IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injection, caused by improper validation of input by the HOST he…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0933

Published Dec 15, 2021

In onCreate of CompanionDeviceActivity.java or DeviceChooserActivity.java, there is a possible way for HTML tags to interfere with a consent dialog due to improper input validatio…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44042

Published Dec 14, 2021

An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encod…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-38182

Published Dec 14, 2021

Due to insufficient input validation of Kyma, authenticated users can pass a Header of their choice and escalate privileges which can completely compromise the cluster.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43410

Published Dec 9, 2021

Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being esca…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42250

Published Nov 17, 2021

Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41232

Published Nov 2, 2021

Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there is an LDAP injection vulnerability which affects instances…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41191

Published Oct 27, 2021

Roblox-Purchasing-Hub is an open source Roblox product purchasing hub. A security risk in versions 1.0.1 and prior allowed people who have someone's API URL to get product files w…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21684

Published Oct 6, 2021

Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a build cause, resulting in a store…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33672

Published Sep 14, 2021

Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message. When the message is accepted…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-39170

Published Sep 1, 2021

Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There i…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22254

Published Aug 20, 2021

Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-38751

Published Aug 16, 2021

A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can change links on the webpage to an arbitrary value, leading to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32072

Published Aug 13, 2021

The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to get source code information (disclosing sensitive application data) due to insufficie…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 475 CVEsPage 16 of 19